Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). An authenticated user holding only low-privileged access can cause an internal error condition in Kibana by supplying specially crafted data. The resulting error is raised on an execution path so it propagates as an uncaught exception and terminates the Kibana process. Kibana is unavailable to all users until the service is restarted, and the condition can be triggered repeatedly.
{
"cna_assigner": "elastic",
"cwe_ids": [
"CWE-248"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72660.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"last_affected": "8.19.19"
},
{
"introduced": "9.0.0"
},
{
"last_affected": "9.3.7"
},
{
"introduced": "9.4.0"
},
{
"last_affected": "9.4.4"
}
],
"source": "AFFECTED_FIELD"
}
]
}{
"cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.19.20"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.3.8"
},
{
"introduced": "9.4.0"
},
{
"fixed": "9.4.5"
}
],
"source": "CPE_RANGE"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72660.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "115913013950776467682935266167186214290",
"length": 443
},
"id": "CVE-2026-72660-0394a091",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/ml/utils/MlIndexAndAlias.java",
"function": "hasFieldTypedAs"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"283190670438501987514727838726815920477",
"139872482520600089094968553951135983484",
"244928736363048457427079246025589015191"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-15fc2a3d",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighterTests.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"81816716326784163141037864156461492390",
"193457615837810166023961203333335140451",
"219949312864961936290517385645475595766",
"193492332273642270123780157420855738475",
"109134945049513130160940169446777743717",
"117749742539505017103393899150508650276",
"327484658846402275517677001025878754632",
"88277128083084399881468861707085467538",
"261752105453815012587785041956160391569",
"45219006148435694893618332155695206738",
"247400239131959349329922561927948738354",
"297143970384114240916019390040752528710",
"219561097176965364021383399693993096195",
"174756042447011514348682282304277857750",
"295187533307863769403119595053335806808",
"127757002294872223858010470453881573595",
"76127827453759183834786055401076437523",
"27862674806732483010218336574864014860",
"139168849936502340267087795027387029590",
"335161156717404889718272437713634409769",
"242204158689472787917814084807122224632",
"228351892385528956460654896704676575935",
"108930408417477068391252722732201965832"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-2ecb32d4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/ml/src/test/java/org/elasticsearch/xpack/ml/MlAnomaliesIndexUpdateTests.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "35973537492193988444530376691395407843",
"length": 2369
},
"id": "CVE-2026-72660-3749bff4",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java",
"function": "setupParser"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"291831910690966635218544031672950971478",
"161152085631897994744104891500764725967",
"127236844828659388597695288999749917490",
"261379068811515202666545085705261440192",
"337682173461037959368100046130311712933",
"208689412399050376270863926713279996472",
"233907370603805937211272082051031503525",
"190417235538415989055244158763197593722"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-4df5c1e0",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/qa/rolling-upgrade/src/test/java/org/elasticsearch/upgrades/MlMappingsUpgradeIT.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"114508176030696626539066047296433779214",
"43384607500169746049581282043376952148",
"283563727296098110195444588655154165811",
"277031765205288332698033581440269116720",
"187407052376657667672985622362187421922",
"90126549817761157374395826113896432271",
"62431126033836515299954878706677890458",
"276372619117036678140958072933552714348",
"34204804071724460000309539643270206424",
"178874689487166837173458238589286447776"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-56785d56",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"130974301542137558840448047842862618269",
"310384723823813034858297363478666431577"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-5cd5b1b7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/core/src/test/java/org/elasticsearch/xpack/core/ml/utils/MlIndexAndAliasTests.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"233121128229985219156668576977333876288",
"322038067866141381526771770641116867245",
"241430259805230103725201070300611475508",
"71318714060438215369602882120931554844",
"19463283512534906609410116339369250684",
"103496732783466577522595948932409730311",
"155310668681586578284879423735099690318",
"63301931713071047032833396515427666185",
"172640144808196375156343472350222055588",
"229896768205556589988297775201735715505",
"47208004096404474157949582568811506150",
"126854002759364804916266098874108951477",
"14107338448903472933351885960178041593",
"66745378341942989349900429020686187568",
"262821386059642390664811956572796391799",
"31104652174867756272822497479626521413",
"151910984870007046939085084370763218351"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-6460fc3c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/core/src/main/java/org/elasticsearch/xpack/core/ml/utils/MlIndexAndAlias.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "74600334261879604741521313242640339568",
"length": 4662
},
"id": "CVE-2026-72660-687797ed",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java",
"function": "highlight"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "10160088286724545746756661846724288313",
"length": 176
},
"id": "CVE-2026-72660-6e669937",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java",
"function": "getFieldType"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"101393873990096950420991800416251882918",
"23490955719992678536167815105830831478",
"275894198653151692933552380072493919347",
"202501215400856585332211908356249536154",
"38093348454503211711412222191970061779",
"245246626249461445125795220025727028592",
"180958960369218863836974260262140085967",
"337350380980350042081781305366538775470",
"209841966927085880094961636819164294326",
"161393650047555658935815194508550352145",
"330517082616902116482067993370942531899",
"139204962687075029824507759713221564811",
"23092223225320115423316205456624802397",
"37420460032820905945586347346833340838",
"56751750874276172321310225949913672733",
"139074372557140290886430200439833044447",
"141385189185576989096725233165411591300",
"206795474029433025082976745152568547550",
"198930134595639097471839755328603906939",
"159807356369538152020721402072228673398",
"117728750679808310613840053309847667139",
"172906292808846080081860718130397529035",
"77382181164524361686824059687819226277",
"81986912303227812355627883674974956034",
"245767764611893032166803726880040920216",
"231099459878349177561531680968163033991",
"6669464796606121548655461477703233517",
"135583465348717599625336164574164606818",
"242389645836035778480535609937826583277",
"111675281323712967699314260735726811809",
"165445570640752170002877819503430379486",
"166261080474479085574148431053135176552",
"109311873620279040957844750750051860908",
"246755689251828643152877627567504552117",
"239899546813507800298746642496596055672",
"212209778102963534965342299609543145657",
"282878794880246854237680563971348320616",
"74624459302890992150581015592478906823",
"173196531197277496905860757850433510424"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-7d2dcc21",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlAnomaliesIndexUpdate.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "303281486317530552893821687171494518785",
"length": 1255
},
"id": "CVE-2026-72660-83301d6d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlAnomaliesIndexUpdate.java",
"function": "healOneBadIndex"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "161461265920098109707747385294147369779",
"length": 1809
},
"id": "CVE-2026-72660-89723ca9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlAnomaliesIndexUpdate.java",
"function": "emitAdvisoryNotifications"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"130192812032915568189929366428112074279",
"338587668112843751875004607897056457244",
"311636223832287298418351940618914661904",
"14559433973571236327103093772803942734",
"81766092491860980139880041074416541030",
"83778004218823664808743686188872036723",
"217672029278899031516016760140755058444"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-9734acfc",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/main/java/org/elasticsearch/rest/action/search/SearchCapabilities.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"280077327868295105608486500378173092851",
"43015048598310775409495333102726391169",
"137751066797260795582560576962541718966",
"142113089162365310946470839866993266027"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-afcc8302",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/ml/src/main/java/org/elasticsearch/xpack/ml/MlIndexTemplateRegistry.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"243868588130949656791143692081236563864",
"311505216586199373294314499230294889565",
"23300629379259170631342652985157100415",
"99779525804820300359777388439313924719",
"124392759507223488964887386448798184793",
"57056074566821104672192600168236166604",
"183428232184500482658775793061523078930"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-bd63b83e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/AbstractHighlighterBuilder.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "195251013402414028464036428127401944068",
"length": 757
},
"id": "CVE-2026-72660-bebcec38",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/qa/rolling-upgrade/src/test/java/org/elasticsearch/upgrades/MlMappingsUpgradeIT.java",
"function": "testMappingsUpgrade"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"122639132757664986803138175691671001655",
"335892283999867396276535502941166644649",
"252845685254806679929754126735709659653",
"70459544080609156892578956654685198979",
"288350301639674802567568120843372854348",
"128879439556083118790804565740578695567",
"183568503689704087885138164738553210791",
"315988264130765396628199666193426980549",
"110105306531665817097053229432225710351",
"108886619290626151118397149603734671098",
"68900764452827513161409585113073530589",
"109699481272201296627752008736891181922",
"89552474233322494405147063649180198152",
"243794874480578150177830085733756836217",
"128936352400535787295390066296206280301",
"168193967744077208144892951303807415035",
"32485489507345202777470620624306770167",
"82468793747458534960176489784612968344",
"95431536162858288727547312167888083055",
"79895802567313409968279279144916310561",
"109983373614664327492018760324106301607",
"254164139643632659290414288579740637195",
"218911482828271878345863242741149783938",
"290149128642774742559654272690374710990",
"129649976829885946269329561068451864187",
"271521553609249011929656203339955131993",
"116967678018103273313850160203491775016",
"34507466461561024444180968955125864688",
"149539466270008484339757108260134471872",
"241540141246676079432554907112288153733",
"247281622777097759942516432384261889326",
"8682106367820934505412234917026602498",
"258599880353756871245323998211345504441",
"140682565192181975671989624265695960587",
"100268892565605616091333444189761449681",
"214950598829781998119271592022997186976",
"200550104524719405385075838124186899375",
"313720121068230248463194804287647092807",
"188167255630204728049901172366742944889",
"197051329735330186721065881872811534640",
"246392715163119707808625433035684232434",
"127945619089996738346525337879859203179",
"136702270964155933380398036066653195170"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-ca3692e7",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"55892219538835031952319089164074182258",
"98893125584566396768016509024864438414",
"19458546747287293758961852067136502121",
"184762767260389321870124416427883759205",
"111219214059868615047400935392923393010",
"45724314446742059907257730571042785532",
"179713398058643943713754786096284698281"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-cfefdc32",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/171dd53e53c29b91f45d2d87857a3f74db48cca5",
"target": {
"file": "x-pack/plugin/ml/src/test/java/org/elasticsearch/xpack/ml/MlIndexTemplateRegistryTests.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "186492591955110081095185334864085897708",
"length": 674
},
"id": "CVE-2026-72660-dc0a4f96",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilder.java",
"function": "build"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "50460798663850937323875144151113267593",
"length": 3586
},
"id": "CVE-2026-72660-e5c86fee",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/test/java/org/elasticsearch/search/fetch/subphase/highlight/HighlightBuilderTests.java",
"function": "testBuildSearchContextHighlight"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"250502453778712768962053518703255093608",
"293745187741608286289486472330502044902",
"92285933861987769382932879499624280339",
"48848052402887098574079705828368727963",
"180954780310110417851376237840132855867",
"265701660666103015958674140349152633739",
"219483656979539974598819100907886798376"
],
"threshold": 0.9
},
"id": "CVE-2026-72660-f6f0ec86",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/elastic/elasticsearch/commit/adc1f04ffdd393d1977990338d5512c5eaf1ce94",
"target": {
"file": "server/src/main/java/org/elasticsearch/search/fetch/subphase/highlight/PlainHighlighter.java"
}
}
]
"2026-09-04T08:06:33Z"
{
"cpe": "cpe:2.3:a:elastic:kibana:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "8.0.0"
},
{
"fixed": "8.19.20"
},
{
"introduced": "9.0.0"
},
{
"fixed": "9.3.8"
},
{
"introduced": "9.4.0"
},
{
"fixed": "9.4.5"
}
],
"source": "CPE_RANGE"
}